March 10, 2021 By Raymond Xu < 1 min read

The SDK-for-Node.js buildpack includes the community January/February 2021 security releases and updated Node.js runtimes.

The January 2021 security release includes fixes for the following: 

  • Use-after-free in TLSWrap (High) (CVE-2020-8265), which impacts all 10.x, 12.x, and 14.x runtimes.
  • HTTP Request Smuggling in nodejs (Low) (CVE-2020-8287), which impacts all 10.x, 12.x, and 14.x runtimes.
  • OpenSSL – EDIPARTYNAME NULL pointer de-reference (CVE-2020-1971), which affects all 10.x, 12.x, and 14.x runtimes.

The February 2021 security release includes fixes for the following: 

  • HTTP2 ‘unknownProtocol’ cause Denial of Service by resource exhaustion (Critical) (CVE-2021-22883), which impacts all 10.x, 12.x, and 14.x runtimes.
  • DNS rebinding in –inspect (CVE-2021-22884), which impacts all 10.x, 12.x, and 14.x runtimes.
  • OpenSSL – Integer overflow in CipherUpdate (CVE-2021-23840), which impacts all 10.x, 12.x, and 14.x runtimes. 

This buildpack contains the following Node.js runtimes: v10.23.3, v10.24.0, v12.20.2, v12.21.0, v14.15.5, v14.16.0. It is based on the community Node.js buildpack v1.7.44. The latest v10 runtime is the default runtime when one is not specified in the package.json. An existing application will not be affected by the new buildpack until you redeploy or restage. New applications will automatically use the new buildpack.

Learn more

More from Cloud

24 IBM offerings winning TrustRadius 2024 Top Rated Awards

2 min read - TrustRadius is a buyer intelligence platform for business technology. Comprehensive product information, in-depth customer insights and peer conversations enable buyers to make confident decisions. “Earning a Top Rated Award means the vendor has excellent customer satisfaction and proven credibility. It’s based entirely on reviews and customer sentiment,” said Becky Susko, TrustRadius, Marketing Program Manager of Awards. Top Rated Awards have to be earned: Gain 10+ new reviews in the past 12 months Earn a trScore of 7.5 or higher from…

Helping enterprises across regulated industries leverage hybrid cloud and AI

3 min read - At IBM Cloud, we are committed to helping enterprises across industries leverage hybrid cloud and AI technologies to help them drive innovation. For true transformation to begin, we believe it is key to understand the unique challenges organizations are facing—whether it is keeping data secured, addressing data sovereignty requirements or speeding time to market to satisfy consumers. For those in even the most highly regulated industries, we have seen these challenges continue to grow as they navigate changing regulations. We…

Migration Acceleration Program for IBM Cloud

2 min read - The cloud has emerged as a transformative technology platform, offering flexibility, scalability and cost-effectiveness. Enterprise cloud migration strategies seek to be business-driven with an integrated technology, operational and financial adoption plan. Knowing where you are, where you are going, and how you get there is critical to sustainable success. Building an end-to-end plan with confidence can be a daunting undertaking, and enterprise leaders find it challenging to design and execute a cloud migration plan. To address these challenges, we continue…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters